ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

DB2 flaw leaves database defenceless

Martin LaMonica CNET News.com

Published: 18 Sep 2003 08:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security flaw in Linux editions of IBM's DB2 database could allow unauthorised users to seize control of a database's contents, Big Blue has revealed.

IBM said that the problem affects version 7 of its DB2 database for Linux. The company posted a patch, called FixPak 10a, on its Web site. IBM also is expected to update its usual DB2 version 7 technical support page with the latest fix.

The flaw was uncovered by Boston security company Core Security Technologies, which alerted IBM. Core Security Technologies plans to issue an alert on the vulnerability on Thursday.

Engineers at the security company said the vulnerability, which could allow a person to get "root" privileges to a DB2 database, is simple to exploit. A company employee, for example, with only limited database access rights could trick the system into giving him or her access to the entire data store.

"This flaw is serious because it allows somebody to get control of a system...DB2 is a database, and we assume there is sensitive information in the database," said Paul Paget, chief executive of Core Security Technologies.

The vulnerability allows a hacker to launch a "buffer overflow" attack by sending a long command to a file in the DB2 database, which dictates access privileges, according to Core Security Technologies. With a buffer overflow, hackers can take control of a system and implant unwanted programs.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
41 out of 82 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Core Java programmer - Government

Core Java programmer - My Government client seeks a core Java / J2SE programmer to join their team, to develop the middle-to-back end of a real-time ...

Core Java/J2EE Analyst Programmer

My client is in search for a solid Core Java Developer (Java/J2EE), within extensive business knowledge. CORE REQUREMENTS: - Extensive Application ...

Core VOIP Analyst / VOIP / Avaya / Cambridge

Core VOIP Analyst / VOIP / Avaya / Cambridge Salary:(incl on-call allowance) 31,000 - 38,500 depending on experience. The Role of the VOIP Analyst: ...

Featured Talkback

Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Discussions

187205 187205

Companies to react to downtime

Thursday 24 July 2008, 2:51 PM

1 comment
pearce_jj pearce_jj

Defragging: Merits?

Thursday 24 July 2008, 2:19 PM

13 posts
David Long David Long

Defragging: Merits?

Thursday 24 July 2008, 10:30 AM

13 posts

Vista Upgrade Blog

Microsoft's pre-modern message puts a...

Over at ZDNet.com, Ed Bott reports a first sighting of Microsoft's eagerly awaited $300 million ad campaign. Already the cause of much speculation, the consensus is that this will be... More

7 comments

A $40 CONSUMER-class router has create...

Believe it or not I don't work in IT, haven't for 7 years. Yes I work with Microsoft's Windows XP Embedded and as a result I have to know a lot about the OS, the kernal, Win API calls... More

Post a comment

Sick Puppy Redo

I generally follow a dispassionate investigative process when trying to discern what happened when a project goes bad. Although its a low priority item, it gets done simply because... More

Post a comment